Chains and currencies
Wallet creation and the CLI default to Tempo Testnet. Payment requests use the selected wallet’s network and have no testnet default of their own. Mainnet setup is an explicit choice in the CLI.
For a headless mainnet setup, specify both the chain and acknowledgement, for example
--chain 4217 --confirm-mainnet. Interactive mainnet setup displays a real-funds confirmation before creating any resources.
Explorer URLs
Each Tempo network has its own canonical explorer.
EVM chains use the standard block explorers (
basescan.org, etherscan.io, etc.) and Solana uses solscan.io / explorer.solana.com.
Wallets
POST /api/wallets uses these defaults when a field is omitted:
Custody priority
The payment evaluator selects wallets in this order when an agent has multiple linked wallets:MANAGED > SMART_CONTRACT > EXTERNAL
Agent-wallet links
POST /api/agents/{id}/wallets applies these defaults. Linking a mainnet wallet to a DEV or
STAGING agent succeeds but returns a warnings entry, because only PROD agents can pay from
mainnet wallets.
For wallet-level spend limits,
null means no cap and 0 blocks all payments through the link.
To remove a cap, set the field to null with PATCH /api/agents/{agentId}/wallets/{walletId}.
External-wallet auto-create
WhenPOST /api/sdk/payments/approve is called with a senderAddress that does not exist in the organization, Conto creates an EXTERNAL wallet automatically with:
delegationType is a label on the agent-wallet link. It does not loosen the spend limits or
policies. enforcementMode: MONITORING_ONLY means Conto does not hold this wallet’s keys. It checks
payments sent through approve and cannot block a transfer the wallet signs outside Conto. See
wallet custody.
Tighten these via PATCH /api/agents/{agentId}/wallets/{walletId} before relying on them in production.
Approval tokens
Tokens are single-use. After expiry, request approval again.
SDK keys
Full keys are returned only once at creation. Store them immediately.
Payment requests
Policy evaluation
Counterparties
A new counterparty record starts at
0.5 with level UNKNOWN. Conto sets the level from the ranges below each time it rescores the counterparty, for example after a confirmed payment. TRUSTED also requires a verified counterparty, otherwise the level stays VERIFIED. Below 0.2 the level is BLOCKED only when there are adverse signals such as failed or flagged transactions, otherwise UNKNOWN.
Rate limits
See Rate limits.Pagination
Response envelopes vary by endpoint. See API conventions.
Webhook delivery
Auto-freeze thresholds
Automatic protection is off for new agents (enabled: false). These are the default thresholds:
Tunable via
PATCH /api/agents/{id}/freeze-config. See Automatic agent protection.
Org roles
OrgRole enum: OWNER, ADMIN, MANAGER, MEMBER, VIEWER. New members default to MEMBER.
See Roles and permissions for the permission matrix.